ChainBleedv0.1 · open intel
← back to feed·AVAX2024-02-23 · 2y ago
Incident · SLOWMIST

Avalanche

Security Vulnerability
Estimated loss
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
Undisclosed
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

On February 23rd, the Avalanche mainnet experienced block production interruptions. Addressing this issue, Ava Labs co-founder Kevin Sekniqi stated on Twitter that the problem appears to be a gossip-related mempool management error, which is purely a code-related issue, not a performance handling problem. It seems that inscriptions have reached an edge case, but they did not affect performance. The mainnet downtime issue appears to be related to an edge-case bug in mempool processing, and bug fix testing is currently underway on the Avalanche testnet. On February 24th, Ava Labs engineering lead Patrick O'Grady tweeted that nodes need to be upgraded to AvalancheGo version 1.11.1, which disables the logic added in v1.10.18 that caused validators to send excessive amounts of gossip to each other. Avalanche Validators provision a stake-weighted bandwidth allocation for each peer, and this flawed logic led each node to saturate their allocation with useless transaction gossip. This dynamic prevented pull queries issued by validators from being processed in a timely manner and resulted in consensus stalling. Attack method (per SlowMist): Security Vulnerability. Reported loss: -.

Primary source
https://twitter.com/_patrickogrady/status/1761057598143643696
Sourced from
slowmist
Technical record
chain
avalanche
protocol
Avalanche
bug_class
unknown
date_occurred
2024-02-23
loss_usd
source_id
sm:avalanche::2024-02-23
Related — same bug class
2026-05-16
25d ago
ETH
Adshares
Bridge-Minter Fake-Mint Exploit (wADS)
bridge
$628.0K
AMBIGUOUS
2026-05-15
26d ago
MULTI
THORChain
Cross-Chain Router Exploit (multi-chain drain)
bridge
$10.70M
AMBIGUOUS
2026-05-13
27d ago
BSC
Mail Token
BSC token contract exploit (vector undisclosed)
accounting
$54.6K
UNRATED
2026-05-13
27d ago
ARB
ShapeShift FOX Colony (Colony Network)
executeMetaTransaction → resolver-repoint via setTarget → delegatecall drain
access-control
$132.7K
AUDIT-CATCHABLE
2026-05-13
28d ago
ETH
Transit Finance
Contract Vulnerability
logic
$1.88M
UNRATED
2026-05-13
28d ago
ETH
TAC Cross-Chain Layer (TON Side)
Contract Vulnerability
logic
$2.80M
UNRATED
ChainBleed — live web3 threat intelligence